Short answer: The proposed HIPAA Security Rule update would make multi-factor authentication mandatory for any system accessing ePHI, removing the flexibility practices currently have to treat MFA as an addressable safeguard. That proposal remains unfinalized, with HHS now targeting mid-2027 for final action. But MFA is inexpensive, widely available, and already a reasonable security practice under the current rule — making it one of the easiest items on the proposed update to get ahead of now, independent of the rule's eventual outcome.
Why MFA specifically gets singled out
Of everything in the proposed update, MFA stands out because it's simultaneously one of the most impactful security controls and one of the cheapest to actually implement. Most modern EHR, billing, and email platforms already support MFA as a built-in feature — the barrier for most small practices isn't cost or technical complexity, it's simply that MFA was never turned on, or wasn't made mandatory for staff who could otherwise opt out.
Where to check right now
Your EHR or practice management system. Confirm MFA is available and actually enforced for every user account, not just optional for whoever chooses to enable it.
Billing and payment platforms. Any system handling patient billing or payment information should have MFA enforced the same way as your clinical systems.
Email, especially shared or admin accounts. Shared inboxes and administrative email accounts are frequently overlooked for MFA specifically because multiple people need access — but that makes them a higher-value target, not a lower one.
Cloud storage and backup systems. If patient records are backed up to a cloud service, that access point needs the same MFA enforcement as your primary systems.
Remote access tools. Any VPN, remote desktop, or remote access software used by staff, especially for after-hours or telehealth-related access, should require MFA.
Common reasons practices haven't turned this on yet
- Assuming a strong password is sufficient, without recognizing that MFA protects against a fundamentally different category of threat (a stolen or guessed password) than password strength alone addresses
- MFA being available in a system's settings but simply never activated, often because nobody was specifically responsible for checking
- Concern that MFA will slow staff down or create friction — a real consideration, but one that's generally outweighed by the security benefit, and modern MFA methods (push notifications, authenticator apps) add only seconds to a login
What "MFA ready" actually looks like
Being genuinely ready means MFA is enforced, not just available, across every system with access to ePHI — and that this is documented as part of your written Security Rule policies, not just an informal practice some staff follow and others don't. If the proposed rule's mandatory MFA requirement does eventually finalize, practices that have already enforced this consistently will have essentially nothing left to change on this specific item.
Why this is worth doing now regardless of the rule's status
Independent of whether or when this proposal becomes final, MFA is already the kind of safeguard a current risk assessment should be identifying as a gap if it's missing. Waiting for a mandate that might not arrive until 2027, or might change in scope before then, isn't a good reason to leave an inexpensive, high-impact control turned off in the meantime.